exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

citadel.txt

citadel.txt
Posted Apr 13, 2004
Site citadel.org

Citadel/UX Security Advisory 2004-01 - Citadel/UX versions 5.00 through 6.14 had loose permission settings for database related files, allowing any local shell user to gain access to any data on the system.

tags | advisory, shell, local
SHA-256 | 9528e6e8eb10b9e85b444a257f9d75e05e65db8af8dbc32634e6006f86f7eb36

citadel.txt

Change Mirror Download
Citadel/UX Security Advisory 2004-01

1. Topic:

Updated Citadel/UX package fixes permissions problem which could allow
local users direct access to the Citadel/UX database.

2. Relevant releases/architectures:

Citadel/UX 5.00 - 6.14, all architectures

3. Problem description:

Citadel/UX is a high performance, multithreaded messaging server which
provides multiple access methods including Web, POP3, IMAP, SMTP and
native Citadel protocols. It provides email, public forums, mailing
lists, instant messaging, multiple/virtual domain support,
calendaring/scheduling, single-instance message store, and many other
features.

In older Citadel/UX releases, the "data" directory, where Citadel stores
its database files, had permissions drwxr-xr-x (0755) set, and the data
files were -rw-r--r-- (0644). This allowed any local user to view the
database directly, bypassing access controls to read messages which the
user is not authorized to read or to extract user data such as
addresses, phone numbers and passwords.

This vulnerability affects only systems where an attacker is able to
gain a local shell on the affected machine.

This vulnerability primarily affects users whose original Citadel
installations were version 5.xx or older software. The permissions have
been correct for all new 6.xx installations; however, installations
which have been upgraded from 5.xx to 6.xx may be vulnerable.

4. Workaround:

# chmod 700 $CITADEL/data

where $CITADEL is the directory in which Citadel/UX is installed
(typically /usr/local/citadel).

5. Solution:

Install Citadel/UX 6.20p1 from the source code distribution.

Citadel/UX 6.20 ensures at startup that the data directory is not world
readable or executable and that database files are only readable by Citadel.

Sites which currently use Citadel/UX 5.90 or prior should read the
installation directions in docs/citadel.html carefully for significant
changes. Upgrading from 5.90 or prior may require a maintenance window
of 30-60 minutes so that Citadel can upgrade the data file formats.
Upgrading from 5.91 or later requires only shutting down the old server
and restarting the new server.

Download Mirrors:

US (fast): http://my.citadel.org/download/citadel-ux-6.20p1.tar.gz
US (slow):
http://uncensored.citadel.org/pub/citadel/citadel-ux-6.20p1.tar.gz
ibiblio: Available on ibiblio.org within a few days.

md5sum: 98c0124aeaf6e3e0003edf91659fade2 citadel-ux-6.20p1.tar.gz
sha1sum: def7650e2af43a7adc6f2621887ae1b62b1b57d0 citadel-ux-6.20p1.tar.gz

6. Contacts:

Citadel/UX Development Team: <devel@citadel.org>
Citadel/UX Home Page: http://www.citadel.org/
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close